Conversation

It's as if people don't believe me when I say "you must upgrade"...
Quote Tweet
Today from the tales of "always use really fresh #Linux #kernel versions, as they fix security issues not yet disclosed": * use-after-free in io_uring (fixed in 5.10.2) openwall.com/lists/oss-secu * local priv escalation via futexes (fixed in 5.10.12) openwall.com/lists/oss-secu
Image
8
198
Replying to
And what to do with things that you only realize were "security bugs" after the fact? Like, um, 3 years after the fact (one famous bug fix of mine...)? Why wouldn't you upgrade to fix known bugs be they "security" related or not? What is the downside?
3
6
Replying to and
i mean, one downside is when you have ARM chips that require outdated and heavily modified kernel trees (i.e. literally every Android device) so you can't update and can only backport the security patches you know about :)
2
1
Even with GKIs, they still have to actually start shipping the longterm kernel updates reasonably quickly. We used to be promptly applying each longterm release ourselves but it doesn't make much sense for us to be spending our resources on it right now with everything going on.
1
I don't understand how something that a single person can do with a couple days dedicated it to every month is beyond the capabilities of companies like Google and SoC vendors. They need to get rid of the unnecessary per-product/carrier branches/tags and do this important work.
1
Show replies